# openfortivpn: a GPL-3.0 Fortinet VPN client that drives pppd instead of a GUI

> openfortivpn is a command line client for Fortinet PPP+TLS VPN gateways. It spawns pppd, needs root for three specific setup steps, and is not a replacement for FortiClient on Windows.

**adrienverge/openfortivpn** — Client for PPP+TLS VPN tunnel services

- Repository: https://github.com/adrienverge/openfortivpn
- Stars: 3,427 · Forks: 379
- Language: Perl
- License: GPL-3.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/adrienverge-openfortivpn

## What openfortivpn does that a Fortinet GUI client does not

openfortivpn is a client for PPP+TLS VPN tunnel services, and the README states it is compatible with Fortinet VPNs. It is not a full tunnel implementation in the sense that it terminates the network stack itself. It spawns a pppd process and operates the communication between the gateway and that process. That single design decision explains most of the project's behaviour: the TLS side talks to the Fortinet gateway, and the PPP side is handed to the pppd binary already present on your system.

The audience is narrow and identifiable. It is for people who have to reach a Fortinet gateway from a Linux or macOS machine and want that connection to be a command they can put in a script, a systemd unit, or a container entrypoint. The README's own examples are all one-liners, and the configuration file format is a flat ini file. If your workflow involves clicking a tray icon, this is the wrong shape of tool. If your workflow involves a CI runner that needs to reach an internal host through a corporate gateway, it is the right one.

## How the pppd handoff shapes the whole design

The process model is the part worth understanding before you install anything. openfortivpn handles the TLS session with the gateway, then starts /usr/sbin/pppd and passes traffic between the two. Because pppd is a separate process doing the interface and routing work, openfortivpn needs elevated privileges at three points during tunnel setup, and the README lists them: spawning the pppd process, setting IP routes when the tunnel comes up, and adding nameservers to /etc/resolv.conf when the tunnel comes up.

Those three points are also the three things you can turn off. The README shows a mode that does not set IP routes and does not add VPN nameservers, using --no-routes --no-dns --pppd-no-peerdns. That is a real split-tunnel escape hatch, and it is also the honest admission that route and DNS manipulation is a side effect of the client rather than its core job.

The dependency on pppd is the sharpest constraint. The README notes that on platforms with pppd older than 2.5.0, such as the current version of macOS, you should configure with --enable-legacy-pppd. So the pppd version is not an implementation detail you can ignore; it changes how you build the project.

## Installing openfortivpn from a distribution package

The README points to existing packages on Fedora and CentOS, openSUSE and SLE, Gentoo, NixOS, Arch Linux, Debian, Ubuntu, Solus and Alpine Linux. On macOS, both Homebrew and MacPorts provide an openfortivpn package. The Homebrew route is the shortest, and the README gives the two commands:

```bash
# Install 'Homebrew'
/usr/bin/ruby -e "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/master/install)"

# Install 'openfortivpn'
brew install openfortivpn
```

On MacPorts the equivalent is a single privileged install, and the README shows it as sudo port install openfortivpn.

If your distribution is not on that list, you build from source. The README lists the build dependencies per platform: gcc, automake, autoconf, openssl-devel, make and pkg-config on RHEL-family systems; gcc, automake, autoconf, libssl-dev, make and pkg-config on Debian and Ubuntu; net-dialup/ppp and pkg-config on Gentoo. Then:

```bash
./autogen.sh
./configure --prefix=/usr/local --sysconfdir=/etc
make
sudo make install
```

The README adds that if you target platforms with pppd older than 2.5.0, you should configure with --enable-legacy-pppd instead. Either way, the runtime dependency ppp or pppd has to be installed separately, and on Linux, if you manage your own kernel, CONFIG_PPP=m and CONFIG_PPP_ASYNC=m must be compiled in.

## A first connection and the config file people keep asking about

The simplest connection is a single command. The README's first example is openfortivpn vpn-gateway:8443 --username=foo, which prompts for the password. Add --realm=bar when your gateway expects an authentication realm, and --pinentry=pinentry-mac when you want the password stored through a pinentry program rather than typed.

For anything you run more than once, the config file is the practical path. The README shows openfortivpn -c /etc/openfortivpn/my-config, with the file containing:

```ini
host = vpn-gateway
port = 8443
username = foo
set-dns = 0
pppd-use-peerdns = 0
# X509 certificate sha256 sum, trust only this one!
trusted-cert = e46d4aff08ba6914e64daa85bc6112a422fa7ce16631bff0b592a28556f993db
```

That trusted-cert line is the one to pay attention to. The README's own comment marks it as the sha256 sum of the X509 certificate, and says to trust only this one. Pinning it means a gateway presenting a different certificate will not be accepted, which is the point. The full option list lives in the CONFIGURATION section of man openfortivpn, so the man page rather than the README is the reference you want open while writing the file.

For SAML gateways, the README gives --saml-login as the flag. For certificate authentication without a password, it shows --username= --password= --user-cert=cert.pem --user-key=key.pem, with both credential fields deliberately left empty.

## Smartcards, root privileges and where openfortivpn stops

Smartcard support is the area with the most caveats in the README. It requires openssl pkcs engine and opensc. The pkcs11-engine from libp11 needs to be compiled with p11-kit-devel installed. The README links to issue #464 for a discussion of known issues in that area rather than claiming it is settled. It also warns that Fedora builds will not include engine support unless openssl-devel-engine is installed, and suggests trying pkcs11-provider on OpenSSL 3.0 or later first.

To use a card, you put at least pkcs11: in the user-cert option, and the README shows three levels of specificity, from a bare pkcs11: through pkcs11:token=someuser to a full token URI with model, manufacturer and serial. In most cases the bare form is enough, and p11tool --list-token-urls gets you the URI when it is not. Two limits are stated plainly: multiple readers are currently not supported, and on macOS Mojave the pkcs engine-by-id is known not to be found. Testing has been with a Yubikey under Linux, and the README says other PIV-enabled cards may work.

Root is the other boundary. The README is direct that you need sudo openfortivpn, and suggests a /etc/sudoers.d entry if non-sudoer users need it, with visudo -f /etc/sudoers.d/openfortivpn as the way to create one. That is a real security decision, not a footnote: granting a user the right to run openfortivpn is granting them the right to alter routes and resolv.conf.

## openfortivpn compared with openconnect and with FortiClient

The most useful comparison is with openconnect, because both are command line VPN clients that delegate part of the work to a system component and both are packaged by distributions. The difference is protocol scope. openconnect implements Cisco's AnyConnect protocol. openfortivpn speaks the Fortinet PPP+TLS variant and spawns pppd to carry the tunnel. If your gateway is Fortinet, openconnect is not the tool that matches the handshake, and if your gateway is Cisco, openfortivpn is not either. The choice is made by the gateway vendor, not by preference.

The comparison with FortiClient is about form factor rather than protocol. FortiClient is Fortinet's own client and covers platforms openfortivpn does not, including Windows, which the README does not claim. openfortivpn's advantage is that it is a normal package on Debian, Fedora, Arch, Alpine and Homebrew, so it upgrades with the rest of your system and can be scripted. Its disadvantage is that it inherits every pppd and OpenSSL constraint described above, and that the smartcard path is explicitly less tested. On a managed Windows laptop, FortiClient is the only realistic option here.

## Licence, maintenance and the cost of upgrading

openfortivpn is licensed GPL-3.0, and the repository also carries a LICENSE.OpenSSL file, which matters if you redistribute binaries linked against OpenSSL. For most users who install from a distribution or Homebrew, the practical effect is limited to the usual copyleft obligations if you ship modified binaries. If you are embedding the client in a product, read both licence files rather than assuming the OpenSSL exception covers your build.

The repository is not archived, and the last push was on 2026-09-22. There are no retrieved releases, so versioning appears to move through the master branch and distribution packaging rather than through tagged releases you can pin. That is the real upgrade cost: you are tracking a branch plus whatever your distribution ships, and the pppd version on your machine can change how the client must be built. The README's advice to configure with --enable-legacy-pppd on pppd older than 2.5.0 is exactly the kind of thing that breaks silently when a base image moves. Pin your base image, or build from source in your own pipeline so the configure flags are visible.

## Conclusion

Adopt openfortivpn if you need a scriptable, package-managed Fortinet client on Linux, macOS or a container, and you are willing to run it under sudo and keep pppd installed. Do not adopt it if you need a Windows client, a GUI, or multiple simultaneous smartcard readers. Before rolling it out, verify that your gateway accepts PPP+TLS rather than IPsec, that your pppd version is at least 2.5.0 or that you build with --enable-legacy-pppd, and that the trusted-cert sha256 you pin matches the certificate your gateway actually presents.

## FAQ

### How do I install openfortivpn on Ubuntu?

Ubuntu provides an openfortivpn package, which the README lists alongside Debian's. Installing from the distribution package also brings the pppd runtime dependency into your system's normal upgrade path.

### How do I install openfortivpn on macOS?

Both Homebrew and MacPorts provide an openfortivpn package. The README shows brew install openfortivpn for Homebrew and sudo port install openfortivpn for MacPorts, and notes that on current macOS you may need to build from source with --enable-legacy-pppd because pppd there is older than 2.5.0.

### Where is the openfortivpn config file?

There is no fixed default path in the README; you pass one explicitly with -c, as in openfortivpn -c /etc/openfortivpn/my-config. The options accepted in that file are listed in the CONFIGURATION section of man openfortivpn.

### How do I use openfortivpn?

Connect with a single command such as openfortivpn vpn-gateway:8443 --username=foo, adding --realm=bar if your gateway uses an authentication realm. For repeated use, put host, port, username and a pinned trusted-cert in a config file and run it with -c.

### Is openfortivpn safe?

The README does not make a safety claim, but it does document a trusted-cert option described as the X509 certificate sha256 sum, with the instruction to trust only this one. It also states that openfortivpn needs sudo because it spawns pppd and modifies IP routes and /etc/resolv.conf, so anyone allowed to run it can change your routing.

### How does openfortivpn differ from FortiClient?

openfortivpn is a command line client that spawns pppd and is packaged by Linux distributions and by Homebrew and MacPorts. FortiClient is Fortinet's own client; the README does not claim Windows support for openfortivpn, so Windows users have no equivalent here.

## Sources

- [adrienverge/openfortivpn on GitHub](https://github.com/adrienverge/openfortivpn)
- [Issues](https://github.com/adrienverge/openfortivpn/issues)
- [License: GPL-3.0](https://github.com/adrienverge/openfortivpn/blob/master/LICENSE)
- [README](https://github.com/adrienverge/openfortivpn/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/adrienverge-openfortivpn
